Skip to main content
Breach Signal

Breach report

Consumer Tech

Yahoo

Yahoo says 500 million accounts stolen

Yahoo revealed in September 2016 that a state-sponsored attacker had stolen data from at least 500 million accounts in late 2014, a disclosure that landed weeks after Verizon agreed to buy the company.

Reported by CNN

Records exposed

500M

At least 500 million accounts

Scale vs. largest on file

When
2014 (disclosed 2016)
How they got in
State-sponsored intrusion (spear phishing and forged authentication cookies)
Sector
Consumer Tech

On September 22, 2016, Yahoo confirmed that personal information associated with at least 500 million user accounts had been stolen from its network in late 2014. The company attributed the attack to a state-sponsored actor. The timing was awkward: only two months earlier, Verizon had agreed to acquire Yahoo's core internet business for about $4.8 billion, and the disclosure immediately raised questions about what Yahoo knew and when.

The stolen data included names, email addresses, telephone numbers, dates of birth, passwords hashed mostly with the stronger bcrypt algorithm, and in some cases encrypted or unencrypted security questions and answers. Yahoo said payment card data and bank account information were stored separately and were not believed to be affected. It asked users to change passwords and invalidated unencrypted security questions.

In March 2017, the US Justice Department indicted two officers of Russia's FSB intelligence service and two hired hackers over the intrusion. Prosecutors said the attackers used spear phishing to gain a foothold, copied part of Yahoo's user database, and abused access to Yahoo's account management tool to forge cookies that let them into specific accounts without passwords. Targets included Russian journalists, US government officials and private-sector employees. One of the hackers, Canadian resident Karim Baratov, pleaded guilty and was sentenced to five years in prison; the Russian defendants remain out of US reach.

The fallout extended to Yahoo's leadership and its regulators. An internal investigation found that Yahoo's security team had known of the intrusion in 2014 but that the matter was not properly pursued. General counsel Ron Bell resigned, and chief executive Marissa Mayer gave up a bonus. In 2018 the Securities and Exchange Commission fined Altaba, the entity left after the Verizon deal, $35 million for failing to disclose the breach to investors, the first such penalty against a public company over a cyber incident. Verizon also cut its purchase price by $350 million after this and the larger 2013 breach came to light.

The case became a landmark for corporate disclosure obligations. It demonstrated that a breach can materially affect the value of a deal and that securities regulators are willing to punish companies that sit on known incidents. For users, it highlighted how nation-state attackers target webmail providers to reach specific individuals.

More from the wire

More in Consumer Tech.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.